Beware of Instagram Growth Tools Stealing Login Credentials and Sending Them to Attackers

beware-of-instagram-growth-tools-stealing-login-credentials-and-sending-them-to-attackers

Beware of Instagram Growth Tools Stealing Login Credentials and Sending Them to Attackers

A discovery by Socket’s Threat Research Team has unveiled a malicious Python package named imad213, masquerading as an Instagram growth tool. Created by a threat actor identified as im_ad__213 with the associated email madmadimado59@gmail[.]com, this malware cunningly tricks users into surrendering their Instagram credentials. Deceptive Python Package Targets Instagram Users Promoted with a polished GitHub README and branded as a legitimate follower-boosting service under the guise of “IMAD-213,” the package lures victims through forums and Discord servers with promises of rapid social media growth. – Advertisement – malicious imad213 package. Its detailed installation instructions (pip install imad213) and deceptive safety tips, such as using temporary accounts, create a false sense of security, convincing users to input sensitive data without suspicion. Upon execution, imad213 initiates a covert check with a remote server hosted on Netlify (https://imad-213-imad21[.]netlify[.]app/pass[.]txt) to verify if it can proceed, showcasing a remote kill switch that provides the attacker full control over the malware’s operation. If approved, the tool prompts users for their Instagram login details under the pretense of facilitating growth services, even saving them locally in plaintext to a file named credentials.txt as a social engineering tactic to appear convenient and trustworthy. Malicious website Credential Harvesting However
Read More

Exit mobile version